Windows 11 KB5124008 Is Breaking Always On VPN Connections
KB5124008 is causing Always On VPN failures on Windows 11 systems that use certificate-based authentication, according to administrator reports following Microsoft’s September 2026 Patch Tuesday rollout.
The issue can prevent affected PCs from completing the VPN connection, potentially leaving corporate users without remote access. Reports indicate that Windows 11 24H2 and 25H2 clients are affected.
The problem follows Microsoft’s September 2026 Windows 11 Patch Tuesday update and comes alongside separate RDS failures reported on Windows Server.
KB5124008 breaks certificate-based Always On VPN connections
Reports involve Windows 11 devices connecting to Windows Server 2019 systems running Remote Routing and Access Service, or RRAS, together with Network Policy Server.
An administrator reporting the problem on Microsoft Learn said removing KB5124008 and restarting the affected Windows client immediately restores VPN connectivity.
That behavior points to KB5124008 as the trigger rather than a previously working VPN configuration suddenly becoming invalid.
Certificate negotiation may be failing
The regression appears to occur during certificate negotiation as Windows attempts to establish the VPN connection.
An independent advisor suggested that KB5124008 may have introduced a change to the Windows networking stack or IPsec certificate handling.
Microsoft has not confirmed the exact cause, so administrators should treat that explanation as a possible cause rather than a confirmed diagnosis.
Administrators have limited workaround options
Organizations affected by the issue can pause deployment of KB5124008 through WSUS or Intune while waiting for Microsoft to investigate the reports or release a fix.
Administrators who cannot remove the security update because of compliance requirements can also try moving affected VPN profiles to EAP-TLS authentication through Intune.
Uninstalling or delaying KB5124008 carries a significant security trade-off. Microsoft’s September Patch Tuesday release included 966 security fixes, so removing the update could leave systems exposed to vulnerabilities addressed this month.
Microsoft has not yet confirmed the Always On VPN regression or announced a permanent fix.
Via Neowin
Read our disclosure page to find out how can you help Windows Report sustain the editorial team. Read more
User forum
0 messages